Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to DevSecOps and the ECDE Framework
- Foundational concepts and principles of DevSecOps
- Addressing security challenges within DevOps environments
- Overview of the ECDE exam structure and key domains
Cultivating a Secure DevOps Culture and Mindset
- Embracing security as a shared team responsibility
- Integrating security earlier in the SDLC process
- Aligning stakeholders and defining team roles
Embedding Security in CI/CD Pipelines
- Hardening pipelines in Jenkins, GitLab CI, and Azure DevOps
- Managing secrets and configuring secure environments
- Building secure containers and performing image scanning
Application Security within DevSecOps
- Conducting static and dynamic application security testing (SAST/DAST)
- Scanning open-source dependencies using SCA tools
- Performing secure code reviews and adhering to best coding practices
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes
- Implementing IAM and policy-as-code strategies
- Applying DevSecOps principles in hybrid and multi-cloud setups
Monitoring, Compliance, and Incident Readiness
- Implementing security monitoring and logging within CI/CD
- Automating compliance measures (e.g., NIST, ISO, SOC 2)
- Establishing automated remediation and incident response workflows
ECDE Exam Preparation and Final Lab
- Understanding the ECDE exam format and receiving preparation advice
- Completing a capstone DevSecOps pipeline laboratory
- Conducting knowledge checks and assessing exam readiness
Summary and Next Steps
Requirements
- A solid grasp of fundamental DevOps workflows and associated tools
- General familiarity with the software development lifecycle (SDLC)
- Basic knowledge of application security principles is recommended
Target Audience
- DevOps Engineers
- Application Security Specialists
- Software Developers focused on integrating security into their pipelines
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated